Blogs
-
DNSSEC Adoption Rates in 2026: What Actually Happens When It Fails
How many domains use DNSSEC, what resolver-side validation means for your security posture, and what actually breaks when a DNSSEC configuration fails.
-
Deliverability
How to Stop Exchange Hybrid NDRs from Leaking Internal Group Names to External Senders
In Exchange hybrid environments, non-delivery reports sent back to external senders can expose the names of restricted distribution groups. Here is how to prevent that information from leaking.
-
Deliverability
How to Block External Email from Microsoft 365 Copilot: DLP Configuration Guide
Microsoft's new DLP policy can block Microsoft 365 Copilot from processing external email. Here is what it does, what it does not do, and how to configure it.
-
Deliverability
How Attackers Hacked Thousands of Data Centers: A Guide to BMC/IPMI Vulnerabilities
Security researchers compromised thousands of data center servers using a 20-year-old BMC vulnerability. Here is what BMCs are, which servers are affected, and how to audit your infrastructure.
-
DMARC
The DMARC Subdomain Trap: Why p=reject on Your Root Domain Can Silently Break Your Subdomain Mail
A missing SPF record on one subdomain caused legitimate email to be silently rejected for an email authentication expert who has been doing this for 20 years. Here is why it happens, how to prevent it, and how to catch it before it breaks your mail.
-
DMARC
Are Shared Mailboxes Safe for Payment Approvals? The BEC Risk No One Talks About
Shared mailboxes are convenient for accounts payable teams, but they create an accountability gap that attackers actively exploit in business email compromise (BEC) attacks. Here is why and what actually helps.
-
How to Stop Employees from Leaking Company Data into AI Tools
Practical guide for IT admins and MSPs on preventing sensitive company data from reaching ChatGPT, Claude, and similar AI tools. Covers Microsoft Purview DLP, secure web gateways, browser controls, and the role of email authentication in reducing data exposure risk.
-
Deliverability
How to Stop Employees from Leaking Company Data into AI Tools
Practical guide for IT admins on preventing sensitive company data from reaching ChatGPT, Claude, and similar AI tools. Covers Microsoft Purview DLP, browser controls, network-layer inspection, and the email security foundation that reduces the phishing-driven credential leaks behind most AI tool data exposure.
-
DMARC
Why Email Routing Fails When SPF Passes: The DMARC Alignment Problem
SPF passing does not mean email will arrive. When emails fail for specific domains despite valid SPF records, the missing piece is usually DKIM signature and DMARC alignment. Here is what causes it and how to fix it.
-
DMARC
How to Move Your DMARC Policy from p=none to p=reject Without Breaking Email
Moving your DMARC policy to p=reject is the goal of every email authentication maturity journey. It is also the step most likely to break legitimate email if you skip the preparation. Here is how to do it safely.